Help centre · For airline staff
Integrations: API keys, webhooks and the Operations API
Your airline's data can feed your own tools: a Discord bot, your website, a spreadsheet. Everything here is on Staff → Settings → Integrations.
The Operations API key
Create key gives the airline one key that can read everything in the Operations API but change nothing. It's shown once; only a fingerprint is kept, so copy it straight away. If you lose it, make a new one (the old one stops working).
Send it with each request as the header Authorization: Bearer your-key. Open /api/v1/ops on the site to see every address; the main ones are:
/api/v1/ops/flights: flights in the air now and the ones filed in the last minutes, with the PIREP result./api/v1/ops/pilotsand/api/v1/ops/pilots/FCV0002: the roster, and one pilot's rank, hours and location./api/v1/ops/routes,/api/v1/ops/eventsand/api/v1/ops/ranks: the schedule, upcoming events and the rank ladder, for your own website.
Each key can make up to 120 requests a minute.
Named API keys
With Named API keys on (Optional features), make one key per tool, each allowed only what it needs: Flights, Pilots, Schedule, or Pilot changes (turning a pilot's activity exemption on or off). A key can expire on a date and can be revoked on its own. Up to 10 per airline; the list shows when each was last used.
Webhooks
With Webhooks on, your own server gets a message within seconds when something happens: a PIREP filed or reviewed, a pilot joining or leaving, a rank change, a booking made or cancelled, a flight taking off. Each message is signed, so your server can check it came from Vaeroly (the X-Vaeroly-Signature header, an HMAC of the timestamp and body with the webhook's secret).
Failed deliveries are retried for about 15 hours. Each webhook has a delivery log and a Send a test button. A webhook that has failed for 3 days is switched off and the owner gets an email. Up to 5 per airline (open Log & settings on a webhook for its log and the test button).